Privacy
Privacy Policy
This privacy policy describes what personal data we process at Heimster, what we use it for, who we share it with, and what choices you have.
1. Controller
The party responsible for data processing on this platform is Heimster AG, Zug, Switzerland, operating under the Heimster brand.
This statement applies to the Heimster platform at heimster.ch as well as to related services, communication channels and application processes.
When commercial customers (such as brokers or property managers) use the agency and CRM functions to manage their own contact, prospect or applicant data, Heimster acts in this respect as a data processor on behalf of the respective company, which remains responsible under data protection law; the processing is carried out on the basis of a data processing agreement.
2. What data we process
2.1 Account data
When you register, we process in particular your name, email address and authentication data. If you use a magic link or passkey, we process the technical data required for this.
2.2 Profile, application and document data
Depending on how you use the platform, we process profile data, information about your housing situation, application documents, references, messages, viewing appointments and shared documents. Certain content may contain particularly sensitive personal data, such as copies of ID documents, proof of income or information about your family situation.
2.3 Listing and property data
Providers enter address, property and media data for their real estate. This includes descriptions, features, prices, images and process-related information about the rental or sales process.
2.4 Technical usage data
For the security, stability and operation of the platform, we process technical access data such as IP address, time, requested URL, browser type, referrer and system events. Server logs serve in particular for error analysis, abuse detection and system security.
2.5 Personalisation data
If you select a personalised level, we store search history, viewed listings and preferences derived from them locally on your device and use them to improve your experience. When you are logged in, signals derived from this may be merged with your profile.
2.6 Legal bases
We process personal data in accordance with Swiss data protection law and, where applicable, with the GDPR. Depending on the case, processing is carried out to fulfil a contract, on the basis of legitimate interests, due to legal obligations or based on your consent.
Our legitimate interests include in particular the secure provision of the platform, the prevention of fraud and abuse, quality assurance, the enforcement of claims, the stability and further development of the product and the analysis of usage to improve our services.
3. AI-powered features
Heimster uses AI features for listing texts, search assistance, application letters, summaries, the support assistant and image editing. In doing so, inputs may be transmitted to external service providers, in particular to OpenAI, LLC (USA), Anthropic, PBC (USA) and Replicate Inc. (USA).
- AI-generated content consists of suggestions and must be reviewed before use.
- With AI Staging, uploaded images are temporarily transmitted for processing.
Insofar as AI-powered processes contribute in future to preparing assessments, prioritisations or recommendations, significant decisions with legal or similarly considerable effects remain subject to human review and are not made solely on an automated basis, where applicable law so requires.
4. Connected mailboxes and calendars (Microsoft 365 / Google Workspace)
Providers (brokers, property managers) can optionally connect their own email and calendar account with Microsoft 365 (Outlook) or Google Workspace (Gmail) to Heimster. The connection is made exclusively via the official OAuth process of the respective provider; Heimster never receives the password. The authorisation is granted by the provider itself and can be revoked at any time – in Heimster via “Disconnect mailbox” or directly in the security settings of the respective Microsoft or Google account.
After connecting, Heimster processes the following data from the connected account on behalf of the provider:
- Email (read): inbox and sent messages, in order to detect and classify incoming mail (e.g. genuine enquiry vs. automated message/newsletter) and assign it to the appropriate properties and contacts in the CRM.
- Email (send): sending replies and business messages from the provider's own address when this is triggered in Heimster.
- Calendar: reading the connected calendar for the appointment overview as well as creating, changing and deleting the appointments managed by Heimster (viewings, handovers, manually created appointments), including invitations to participants.
- Profile: the connected email address and the display name to identify the mailbox.
The OAuth tokens required for access are stored encrypted in a key vault; the actual token does not leave this vault. Access is strictly per user – Heimster does not merge third-party mailboxes, and the Heimster team has no access to the emails of the connected mailboxes.
Limited use (Google API Services User Data Policy / Limited Use): The use of information received via Google APIs (Gmail, Google Calendar) complies with the Google API Services User Data Policy, including the Limited Use requirements. In particular:
- We use this data exclusively to provide and improve the mailbox and calendar functions visible to the provider.
- We do not sell this data and do not share it for advertising purposes.
- We do not transfer or use this data for other purposes, except where necessary to provide the function, for security reasons, to comply with applicable laws or as part of a merger/acquisition with consent.
- No human reads this data, except (a) with the provider's explicit consent, (b) for security purposes (e.g. abuse investigation), (c) to comply with applicable laws or (d) when the data is aggregated and anonymised for internal operational purposes.
- No AI training: We do not use data from the connected mailbox or calendar to develop, train or improve generalised or non-personalised AI/ML models. AI features operate exclusively within the provider's own, provider-triggered processing.
The same principles apply mutatis mutandis to Microsoft 365 (Microsoft Graph): access only within the authorised scope, exclusively to provide the functions, no sale, no advertising use and no training of generalised AI models.
5. Disclosure and international data transfers
We only share your data insofar as this is necessary for the operation of the platform, legally permissible or initiated by you. This includes in particular:
- An S3-compatible technical storage and file service for media and documents
- Microsoft Azure for sending transactional emails
- Postmark (ActiveCampaign, LLC, USA) for the reliable delivery of transactional emails
- OpenAI, Anthropic and Replicate as external service providers for voluntarily used AI features
- Geoapify for address and location functions
- Photon/komoot for place search and address suggestions
- OpenStreetMap/Nominatim for address and postal code search
- Swisstopo (geo.admin.ch) for map and geodata
- transport.opendata.ch for public transport connections and travel times
- Umami Analytics for reach and product analytics
Some recipients are located outside Switzerland or the EEA, in particular in the USA. In these cases we rely on appropriate safeguards such as standard contractual clauses and supplementary technical protective measures.
Depending on the function, recipients act as data processors on our behalf or as independent controllers when they process the received data for their own legally permissible purposes. When data is passed on to a provider as part of an application or contact request, that provider processes the received information under its own data protection responsibility.
6. Retention
We store personal data only for as long as this is necessary for the respective purposes or legal obligations exist. Typical periods in the current product logic are:
- Account data until the account is deleted, then with a short security buffer
- Applications for a limited time after the process is concluded
- Messages and communication histories, as a rule until the account is deleted or until deletion as part of our product logic
- Listing and property data, as a rule until deactivation or deletion, subject to legal or documentation-related retention
- Server logs, as a rule 30 days
- Locally stored preferences until you revoke or reset your selection
8. Fraud prevention, security and authorities
We also process personal data in order to detect, investigate and prevent abuse, fraudulent listings, phishing, unauthorised access, violations of our terms of use and other security incidents.
Where necessary, relevant information may be analysed internally, linked with technical security data and passed on to external specialist bodies, advisers, law enforcement authorities, courts or other competent bodies, where there is a legal basis for this or where this is necessary to protect our legitimate interests.
9. Service communication and marketing
We send you product- and contract-related communications insofar as this is necessary for using Heimster. This includes in particular account and security notices, application and viewing updates, message notifications, document requests and transactional emails.
If you activate saved searches, notifications or other optional communication features, we use your contact data to deliver this content to you. General marketing or advertising communication takes place only within the scope of applicable law and can, where provided for, be unsubscribed from at any time.
If a provider contacts you via Heimster – for example because your search or contact profile matches a listing – the respective provider is itself responsible for this communication under data protection and competition law; Heimster only provides the technical infrastructure for this.
10. Your rights
Under the applicable data protection law, you have in particular the rights to information, rectification, erasure, restriction, data portability, objection and withdrawal of your consent. If you are resident in the EEA, you can also contact the competent data protection authority.
We usually respond to requests within 30 days. In complex cases this period may be extended, of which we will inform you.
11. Contact
Please direct questions about data protection to privacy@heimster.ch.

